
Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days
Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.